🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A fintech startup is about to launch production EC2 instances that will store and process card-holder data. Corporate security policy requires a host-based intrusion-prevention (HIPS) agent on each instance, but the licensing purchase will not be completed for another month. Which temporary measure is the most appropriate compensating control to reduce the same risk during the interim period?

  • Deploy AWS Network Firewall with managed intrusion-prevention rule groups to inspect and block traffic to and from the EC2 subnet.

  • Enable AWS CloudTrail data events for the EBS volumes attached to the instances.

  • Move the instances into a private subnet that lacks an Internet gateway.

  • Force all instances to use Instance Metadata Service v2 and disable IMDSv1.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot